IT Security & Privacy

FTC Alleges Hims & Hers Shared Patients' Health Data While Quietly Enrolling Them in Paid Subscriptions

Someone looking for treatment through Hims & Hers could reasonably believe they were beginning a conversation with a medical provider. The company's advertising invited them to connect with a clinician, discuss their symptoms, and determine whether a prescription made sense. According to the Federal Trade Commission, many consumers were doing something else entirely. They were setting a recurring subscription in motion before that conversation ever happened.

CISA Updates Software Bill of Materials Guidance to Expand Supply Chain Transparency

The Cybersecurity and Infrastructure Security Agency has released an updated framework for Software Bills of Materials, broadening the minimum information organizations should include when documenting software components as governments and businesses place growing emphasis on software supply chain security.

Australian Privacy Commissioner Revises Retail Facial Recognition Guidance

The legal fight over Bunnings may be over, but the Office of the Australian Information Commissioner is making sure its lessons are not left behind in a tribunal ruling. The regulator on Tuesday published updated guidance for organizations covered by the Australian Privacy Principles that are considering deploying facial recognition technology in busy, publicly accessible spaces such as retail storefronts. The revisions are not a change in the law. They are a statement of how the Office of the Australian Information Commissioner (OAIC) intends to apply it after the Administrative Review Tribunal's March 2026 decision in the long-running Bunnings case.

BIS Warns Frontier AI Is Giving Cyber Attackers a Cheaper Way In

Anthropic’s Mythos did not merely find a weakness in a computer network. In testing, it followed the weakness through. The frontier artificial intelligence model identified vulnerabilities, developed exploits and carried an attack across multiple stages, adjusting its approach with limited human oversight. In some attempts, it completed a full network takeover. OpenAI’s GPT-5.5, released weeks later, showed similar capabilities and performed slightly better on a benchmark of expert-level cybersecurity tasks.

MAS & Singapore Banks Form AI Taskforce as Frontier Models Redraw the Cyber Threat Landscape

Since May, regulators, banks and financial infrastructure operators in Singapore have been sitting around the same table, confronting a problem that is becoming harder to dismiss with each new generation of artificial intelligence. On Tuesday, that quiet collaboration acquired a name. The Monetary Authority of Singapore (MAS) and the Association of Banks in Singapore (ABS) formally launched the AI-Driven Cyber and Technology Risk Taskforce, or ACT, an industry-wide initiative intended to strengthen the financial sector's defenses against threats created by frontier AI models.

Italy Fines Lusha €2 Million, Says Data Broker's Business Crossed Into GDPR Monitoring

The Italian Data Protection Authority imposed a €2 million fine on Lusha, the U.S.-based data broker, ordering it to stop processing the personal data of individuals in Italy while deleting the data it already holds. Read closely, the ruling is less about the existence of a commercial contact database than about what happens when that database is continuously refreshed, expanded and monetized over time.

Poland's Data Management Act Takes Effect, Reshaping Oversight of Data Sharing

Poland's Data Management Act took effect Thursday, completing a piece of legal architecture that has been waiting for its final support. The European Union's Data Governance Act has applied across the bloc since 2023. What entered into force now is the national legislation that gives the regulation a fully functioning home inside Poland's legal system.